seccomp: always propagate NO_NEW_PRIVS on tsync